Uploaded image for project: 'ActiveMQ Artemis'
  1. ActiveMQ Artemis
  2. ARTEMIS-4060

Upgrade Commons Text to 1.10.0

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 2.26.0
    • 2.27.0
    • None
    • None

    Description

      Apache Commons Text versions prior to 1.10.0 are vulnerable to CVE-2022-42889, which involves potential script execution when processing untrusted input using StringLookup. Direct and transitive references to Apache Commons Text prior to 1.10.0 should be upgraded to avoid the default interpolation behavior.

      Attachments

        Issue Links

          Activity

            People

              robbie Robbie Gemmell
              u14183 Steffen Flemming
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m